OS command injection in IMAP connector

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook

Version Affected Solution
FortiSOAR IMAP connector 3.5.7 and below Upgrade to 3.5.8 or above

Acknowledgement

Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication